Skip to content

build(deps): bump Go to 1.26.6 and upgrade grpc/cel-go/mod for CVEs - #475

Merged
kubernetes-prow[bot] merged 1 commit into
kubernetes-sigs:mainfrom
ajaysundark:bump-go-1.26.6-vulns
Sep 17, 2026
Merged

kubernetes-prow[bot] merged 1 commit into
kubernetes-sigs:mainfrom
ajaysundark:bump-go-1.26.6-vulns

Conversation

@ajaysundark

Copy link
Copy Markdown
Contributor

Description

Bumps the Go toolchain and Docker builder base images from 1.26.0 to 1.26.6 across Dockerfile, Dockerfile.reporter, Makefile, netlify.toml, and go.mod, and updates Go module dependencies to address vulnerabilities detected by govulncheck:

  • Bump Go standard library / toolchain to 1.26.6 (remediates 35 Go 1.26.0 standard library CVEs including GO-2026-5026, GO-2026-4970, GO-2026-5856, etc.).
  • Bump google.golang.org/grpc from v1.82.1 to v1.83.2 (fixes GO-2026-6443, GO-2026-6348, GO-2026-6441).
  • Bump github.com/google/cel-go from v0.29.2 to v0.30.0 (fixes GO-2026-6094).
  • Bump golang.org/x/mod from v0.38.0 to v0.40.0 (fixes GO-2026-6180, GO-2026-6179).

Related Issue

None

Type of Change

/kind cleanup

Testing

Verified locally on Linux amd64:

  • make govulncheck -> No vulnerabilities found.
  • ./hack/verify-all.sh -> passes markdown link check and verify-govulncheck.sh diff check.
  • make test -> all 84 controller specs and unit test suites pass (ok sigs.k8s.io/node-readiness-controller/internal/controller 16.916s).
  • make lint -> golangci-lint (42 linters) and kube-api-linter report 0 issues.

Checklist

  • make test passes
  • make lint passes

Does this PR introduce a user-facing change?

NONE

Generative AI Usage Disclosure

  • No AI tools were used
  • AI tools were used (complete below)

How they were used:
AI coding assistant was used to run govulncheck, identify the specific Go version and module upgrades needed to clear all standard library and module CVEs, run local verification suites (make test, make lint, hack/verify-all.sh), and draft the PR description. All changes and test results were verified locally.

@kubernetes-prow kubernetes-prow Bot added the kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. label Sep 16, 2026
@netlify

netlify Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for node-readiness-controller ready!

Name Link
🔨 Latest commit db3f1ed
🔍 Latest deploy log https://app.netlify.com/projects/node-readiness-controller/deploys/6aab112a8619e300087e27c0
😎 Deploy Preview https://deploy-preview-475--node-readiness-controller.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@kubernetes-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: ajaysundark

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/M Denotes a PR that changes 30-99 lines, ignoring generated files. labels Sep 16, 2026

@Karthik-K-N Karthik-K-N left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/lgtm

Thank you.

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Sep 17, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 5ae4d14 into kubernetes-sigs:main Sep 17, 2026
13 checks passed
@rawadhossain rawadhossain mentioned this pull request Sep 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. kind/cleanup Categorizes issue or PR as related to cleaning up code, process, or technical debt. lgtm "Looks good to me", indicates that a PR is ready to be merged. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants